Skip to content

Add minimum NPM package release age#2116

Open
rmainwork wants to merge 1 commit intomainfrom
rm/add-npmrc-file
Open

Add minimum NPM package release age#2116
rmainwork wants to merge 1 commit intomainfrom
rm/add-npmrc-file

Conversation

@rmainwork
Copy link
Copy Markdown
Contributor

In order to add some time buffer for supply chain NPM attacks, require that package releases be older than 7 days (since these compromises are often found in a few hours)

@rmainwork rmainwork marked this pull request as ready for review April 1, 2026 17:37
@rmainwork rmainwork requested a review from a team as a code owner April 1, 2026 17:37
@rmainwork rmainwork requested a review from RubenSandwich April 1, 2026 17:37
@github-actions
Copy link
Copy Markdown
Contributor

github-actions bot commented Apr 1, 2026

Vercel Previews Deployed

Name Status Preview Updated (UTC)
Dev Portal ✅ Ready (Inspect) Visit Preview Wed Apr 1 17:52:48 UTC 2026
Unified Docs API ✅ Ready (Inspect) Visit Preview Wed Apr 1 17:48:55 UTC 2026

@rmainwork rmainwork changed the title Add npmrc file Add minimum NPM package release age Apr 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants